Salesforce Connected App Security Updates for Docusign Salesforce Integrations
08/09/2026
Docusign is updating all Docusign Salesforce integrations to align with Salesforce's latest connected app security requirements. This affects users of Docusign Apps Launcher, CLM/Gen for Salesforce, IAM for Sales, and Legacy eSignature for Salesforce. In compliance with these guidelines, we are implementing the following security controls:
Proof Key for Code Exchange (PKCE)
Refresh Token Rotation (RTR)
30-day idle timeout for refresh tokens
Refresh token IP allowlists at the connected app level
We recommend installing the latest Docusign Apps Launcher 8.6.2 package from AppExchange. This update ensures full compliance with new security protocols and streamlines the reconnection process. Please review the environment upgrade schedule below:
Date | Deployment Phase | Details |
Aug 22–23, 2026 | Sandbox Deployment (Version 8.6.2) | Push upgrades applied to sandbox orgs |
Sep 8, 2026 | Production Kickoff (Version 8.6.2) | Production org push upgrades begin |
Sep 14, 2026 | Enforcement | Security controls go live for: Refresh Token Rotation (RTR) 30-day idle timeout for refresh tokens Refresh token IP allowlists at the connected app level |
Oct 5, 2026 | Production Wrap-up (Version 8.6.2) | Production push upgrades completed |
Oct 8, 2026 | Enforcement | Security controls go live for PKCE |
Note: Please bookmark and check this page regularly for the latest enforcement timelines.